What the vulnerability does
01Description
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.
Explanation of Vulnerability in Simple Terms
02Summary
Photo Gallery by Ays versions before 5.7.1 contain an input validation flaw that allows high-privileged users to modify site data. An administrator or similarly privileged account can trigger integrity or availability issues through the gallery interface. The vulnerability requires administrative access and does not affect confidentiality.
What an attacker can do
03Attacker Capabilities
Modify or disrupt site data via the gallery interface.
Potential impact on your site
04Site Impact
An admin account with malicious intent or compromised credentials could corrupt gallery data or cause service disruption.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative privileges on the site.
Key dates
06Disclosure timeline
July 9, 2024
CVE published
April 28, 2026
Record updated